33% of PCI SSF you already have
NIST AI Risk Management Framework (AI RMF 1.0) already covers about 33% of PCI SSF, leaving
33 of 49 controls as genuinely new work.
Already covered 8
Likely covered 8
New work 33
What is genuinely new work
Nothing in NIST AI Risk Management Framework (AI RMF 1.0) reaches these. This is the list to scope.
PCI-SSF-01Information security program management
PCI-SSF-02Board and management oversight
PCI-SSF-04Security policy framework
PCI-SSF-13Third-party dependency management
PCI-SSF-18Ongoing monitoring and assessment
PCI-SSF-19Concentration risk management
PCI-SSF-20Exit strategy and transition planning
PCI-SSF-22Incident response and containment
PCI-SSF-23Regulatory reporting requirements
SSLC-1.1Security Responsibility and Resources
SSLC-10.1Software Integrity
SSLC-11.1Stakeholder Communication
SSLC-12.1Software Update Integrity and Verification
SSLC-2.1Software Security Policy
SSLC-3.1Software Security Personnel Skills
SSLC-4.1Threat Identification and Risk Mitigation
SSLC-5.1Software Design Security
SSLC-6.1Secure Coding Practices
SSLC-8.1Vulnerability Disclosure and Response
SSLC-9.1Change Management
SSS-1.1Critical Asset Identification
SSS-1.2Critical Asset Protection
SSS-10.1Sensitive Authentication Data (Module A)
SSS-11.1Terminal Software Module Requirements (Module B)
SSS-2.1Sensitive Data Inventory and Protection
SSS-3.1Critical Asset Cryptographic Protection
SSS-4.1Authentication and Access Control
SSS-6.1Threat and Vulnerability Management
SSS-7.1Secure Software Updates
SSS-8.1Vendor Security Guidance
SSS-9.1Account-Data Protection (Module A)
Show the 16 you already have
PCI-SSF-03Risk appetite and tolerance for IT risk
PCI-SSF-05Roles and responsibilities definition
PCI-SSF-09Encryption and key management
PCI-SSF-16Due diligence and onboarding
PCI-SSF-17Contractual security requirements
PCI-SSF-21Incident detection and classification
PCI-SSF-24Customer notification procedures
PCI-SSF-25Post-incident review and improvement
PCI-SSF-06Network security and segmentation
PCI-SSF-07Endpoint protection and detection
PCI-SSF-08Application security controls
PCI-SSF-10Secure configuration standards
PCI-SSF-11Business continuity planning and testing
PCI-SSF-12Disaster recovery procedures
PCI-SSF-14Critical service identification
PCI-SSF-15Communication and escalation procedures
How this is calculated
Already covered means a mapping runs from a control in NIST AI Risk Management Framework (AI RMF 1.0) to that control. Likely
covered means no direct mapping exists but both frameworks map to the same control in a third
standard. New work means neither. We keep those separate rather than adding them into one
friendlier number, because blending them would present a two-hop inference as a verified
fact.
Coverage is not symmetric.
Run it the other way and you will get a
different number; both are correct.
From 332,959 cross-framework control
mappings across 723 frameworks, 531 of them verified against
their source documents. It does not tell you that you are compliant: a mapped control means
the two standards ask for the same thing, not that you have done it.
Try another pair ยท
Today's edition